Live data from Hacker News

Snowflake

snowflake.torproject.org

21–30 of 61 posts

Re: Snowflake

#21
post #18

Snowflake uses domain fronting[1] for rendezvous. It is the digital equivalent of a spy having their secret meetings inside an unsuspecting friends house, and it always eventually it goes bad for that friend. The technique is heavily used by bad actors and is being blocked by default[2] by some cloud providers. AWS went as far as sending a nastygram to Signal[3] when they tried to roll it out on a wide basis for fear…

> The technique is heavily used by bad actors

Evidence?

Re: Snowflake

#22
post #21
post #18

Snowflake uses domain fronting[1] for rendezvous. It is the digital equivalent of a spy having their secret meetings inside an unsuspecting friends house, and it always eventually it goes bad for that friend. The technique is heavily used by bad actors and is being blocked by default[2] by some cloud providers. AWS went as far as sending a nastygram to Signal[3] when they tried to roll it out on a wide basis for fear…

> The technique is heavily used by bad actors Evidence?

It's in the OSEP course. :)

Re: Snowflake

#23
post #18

Snowflake uses domain fronting[1] for rendezvous. It is the digital equivalent of a spy having their secret meetings inside an unsuspecting friends house, and it always eventually it goes bad for that friend. The technique is heavily used by bad actors and is being blocked by default[2] by some cloud providers. AWS went as far as sending a nastygram to Signal[3] when they tried to roll it out on a wide basis for fear…

When I last looked, the intent was that eventually ECH endpoints offer the same effective service that you got with Domain Fronting, but without messing with the backend in a way which is disruptive for the cloud providers so they support it.

Encrypted Client Hello is the in-progress work to have even the client's initial contact to an HTTPS server be encrypted. https://datatracker.ietf.org/doc/draft-ietf-tls-esni/

Why would ECH be fine when Domain Fronting isn't? The problem with Domain Fronting is that we get surprised too late with the actual request. We get what appears to be a legitimate request for this-thing.example, so we do all the work to respond to a this-thing.example request and then... swerve, sorry I changed my mind, my request is actually about hidden-service.example.

With ECH we (but not an adversary snooping the connection) know immediately that the request is for hidden-service.example and so we don't waste our time setting up for the wrong work.

Re: Snowflake

#24

Earlier quoted context omitted.

"Just" don't connect from an IP that can be tied back to you, use black market sim in a separate phone, connect from places you don't go, turn it off when not in use... It gets expensive fast...

> use black market sim in a separate phone In most countries this takes you from “may have committed a crime” to “have actually committed a crime”

We're talking about countries where using vpn is already a crime so no problem

Re: Snowflake

#25
post #13
post #7

If Tor is illegal in your country, it seems pretty risky to try to use it. Since anyone can run a snowflake proxy, it would be a trivial exercise to just log connecting IP addresses. Then it's a gamble with vanishing odds of staying safe each time you connect.

They could block Snowflakes with IPs from networks in unsafe countries, but that is trivially bypassed by the attacker just buying VPSs (or botnet nodes) in a freer country. Skimming the Technical Overview[0], I don't see anything about mitigating the risks you mention. The purpose of Snowflake seems to be to circumvent blocking of Tor, not to prevent detection of using Tor. It takes advantage of "Domain Fronting" an…

> that is trivially bypassed by the attacker just buying VPSs (or botnet nodes) in a freer country

A.K.A. "living off the economic land"

Re: Snowflake

#26
I have it installed and like seeing the number go up. NUMBER BIGGER = DOPAMINE!!

I'm lucky to be born in Scandinavia, so there is really 0 internet censor, for now.

Re: Snowflake

#28

I have it installed and like seeing the number go up. NUMBER BIGGER = DOPAMINE!! I'm lucky to be born in Scandinavia, so there is really 0 internet censor, for now.

You're just lucky YOU aren't affected yet. Try telling that norwegian poker player who is unable to wire legal poker earnings from a tournament abroad to his bank home. Or to any of the people who made money on crypto who they want to use as security for an appartment loan. Or to someone trying to wire gains from legal online casinos abroad. Or to someone trying to access a web site that the norwegian authorities do not like who are DNS blocked (yes, easy to circumvent for tech people). Goverment and politicians abusing authority and limiting individual freedom is already here and growing. When it starts affecting "most people" it is usually a lot harder to reverse. The norwegian goverment already passed a law that allow mass electronic surveilance. And they want to limit the public's access to goverment records. It's a very slippery slope, left side "social democrazy" (spelled "beuracratic dictatorship") like most of EU. People need to open their eyes and fight goverment overreach now.

Re: Snowflake

#29

> If you switch on the Snowflake below and leave the browser tab open, a user can connect through your new proxy! I am not even sure, if I am getting this right. If I embed an iframe in my website, traffic from Tor users will get tunneled through my user visitor's IP? How does consent works with relay.love? Does my website vistor's IP show up as TOR exit node?

What a strange thing not to require browser consent for.

It asks for the user's consent.

Re: Snowflake

#30

I have it installed and like seeing the number go up. NUMBER BIGGER = DOPAMINE!! I'm lucky to be born in Scandinavia, so there is really 0 internet censor, for now.

You're just lucky YOU aren't affected yet. Try telling that norwegian poker player who is unable to wire legal poker earnings from a tournament abroad to his bank home. Or to any of the people who made money on crypto who they want to use as security for an appartment loan. Or to someone trying to wire gains from legal online casinos abroad. Or to someone trying to access a web site that the norwegian authorities do…

My 2c on your scenarios.

>Try telling that norwegian poker player who is unable to wire legal poker earnings from a tournament abroad to his bank home.

Probably blocked due to terror laws. If you can't Western Union money, there is a REALLY good reason.

Wait until you hear about how we are a cashless society and our bank app for money transfer. That you need mobile ID and bank account to use :) Max tracking. But its very handy.

>Or to any of the people who made money on crypto who they want to use as security for an appartment loan.

Good, I hate crypto shit and I want it to go away. It is all a scam. Get a real job and invest in a real bank. Crypto is all tax fraud scam shit.

>Or to someone trying to wire gains from legal online casinos abroad.

Good, I hate gambling and online casinos. If you have to gamble, do it in my country so the taxes benefit.

>Or to someone trying to access a web site that the norwegian authorities do not like who are DNS blocked (yes, easy to circumvent for tech people).

Yes THIS I agree with. I think ISP DNS blocks piratebay etc here now. Or some ISPs do. It's shit, but I already use a 3rd party DNS provider on my PC and phones.

Your point btw? I am running the Snowflake when my browser is open.

Post reply on HN